# Per-host inputs (all supplied by the root module's for_each). variable "name" { description = "Short host key (e.g. \"prod\", \"dev\"), used in log lines." type = string } variable "host" { description = "IP or hostname to SSH to." type = string } variable "ssh_user" { description = "SSH login user (must be able to sudo)." type = string } variable "ssh_private_key_path" { description = "Path to the private key file for ssh_user." type = string } variable "role" { description = "\"prod\" | \"dev\" — informational." type = string } variable "git_branch" { description = "Branch the host checkout is reset to." type = string } variable "domain" { description = "Public domain. \"\" => no Caddy/TLS (open the app port instead)." type = string } variable "compose_files" { description = "Compose files to layer, in order (dev appends docker-compose.dev.yml)." type = list(string) } variable "openmeteo" { description = "Self-host the ERA5 archive: layer docker-compose.openmeteo.yml + provision the host rclone mount." type = bool default = false } variable "om_data_dir" { description = "Host rclone mount point for the archive bucket (OM_DATA_DIR the overlay bind-mounts)." type = string default = "/mnt/om-archive" } variable "om_bucket_remote" { description = "rclone remote:path for the archive bucket (mounted at om_data_dir)." type = string default = "" } variable "om_rclone_conf" { description = "rclone.conf contents installed to /etc/rclone/rclone.conf. Sensitive." type = string default = "" sensitive = true } variable "om_vfs_cache_max" { description = "rclone --vfs-cache-max-size for the mount's on-disk hot cache." type = string default = "80G" } variable "app_dir" { description = "Checkout path on the host." type = string } variable "repo_root" { description = "Local repo root, used to hash the compose files for the re-apply trigger." type = string } variable "repo_url" { description = "Git remote to clone from if the host has no checkout yet." type = string } variable "app_port" { description = "Port the app binds / is health-checked on." type = number } # ---- Sizing ------------------------------------------------------------------- variable "workers" { description = "uvicorn worker count (WORKERS)." type = number } variable "app_cpus" { description = "App container CPU cap (APP_CPUS)." type = number } variable "db_cpus" { description = "DB container CPU cap (DB_CPUS)." type = number } variable "db_memory" { description = "DB container memory cap (DB_MEMORY), e.g. \"8g\"." type = string } # ---- Secrets rendered into /etc/thermograph.env ------------------------------- variable "postgres_password" { type = string sensitive = true } variable "auth_secret" { type = string sensitive = true } variable "vapid_private_key" { type = string sensitive = true } variable "vapid_public_key" { type = string sensitive = true } variable "vapid_contact" { type = string sensitive = true } variable "google_verify" { type = string sensitive = true } variable "bing_verify" { type = string sensitive = true } variable "mail_backend" { type = string } variable "smtp_host" { type = string } variable "smtp_port" { type = string } variable "smtp_user" { type = string sensitive = true } variable "smtp_password" { type = string sensitive = true } variable "smtp_starttls" { type = string } variable "mail_from" { type = string } variable "mail_reply_to" { type = string } variable "discord_webhook" { type = string sensitive = true } variable "discord_public_key" { type = string } variable "discord_app_id" { type = string } variable "discord_bot_token" { type = string sensitive = true } variable "discord_client_secret" { type = string sensitive = true }